Описание
A flaw was found in libstdc++. An integer overflow can occur when processing large inputs to the aligned operator new in the C++ library. This vulnerability could lead to an undersized memory allocation, potentially causing memory corruption or application instability.
Отчет
This Moderate impact flaw affects applications compiled with older gcc versions on Red Hat Enterprise Linux 8 and 9. An integer overflow in the libstdc++ aligned operator new could lead to undersized memory allocations, potentially causing memory corruption or application instability when processing specific large allocation requests.
Меры по смягчению последствий
Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base, or stability.
Затронутые пакеты
| Платформа | Пакет | Состояние | Рекомендация | Релиз |
|---|---|---|---|---|
| Red Hat Enterprise Linux 10 | gcc | Not affected | ||
| Red Hat Enterprise Linux 10 | mingw-gcc | Not affected | ||
| Red Hat Enterprise Linux 6 | compat-gcc-295 | Not affected | ||
| Red Hat Enterprise Linux 6 | compat-gcc-296 | Not affected | ||
| Red Hat Enterprise Linux 6 | compat-gcc-32 | Not affected | ||
| Red Hat Enterprise Linux 6 | compat-gcc-34 | Not affected | ||
| Red Hat Enterprise Linux 6 | gcc | Not affected | ||
| Red Hat Enterprise Linux 7 | compat-gcc-32 | Not affected | ||
| Red Hat Enterprise Linux 7 | compat-gcc-34 | Not affected | ||
| Red Hat Enterprise Linux 7 | compat-gcc-44 | Not affected |
Показывать по
Дополнительная информация
Статус:
EPSS
7.7 High
CVSS3
Связанные уязвимости
A flaw was found in libstdc++. An integer overflow can occur when processing large inputs to the aligned operator new in the C++ library. This vulnerability could lead to an undersized memory allocation, potentially causing memory corruption or application instability.
A flaw was found in libstdc++. An integer overflow can occur when processing large inputs to the aligned operator new in the C++ library. This vulnerability could lead to an undersized memory allocation, potentially causing memory corruption or application instability.
A flaw was found in libstdc++. An integer overflow can occur when proc ...
A flaw was found in libstdc++. An integer overflow can occur when processing large inputs to the C++ `new` operator. This vulnerability could lead to an undersized memory allocation, potentially causing memory corruption or application instability.
EPSS
7.7 High
CVSS3